Alice
Bob
Mallory (attacker)
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.
This simulator visualizes what "secure protocol design" actually buys you. Alice and Bob run a real Diffie–Hellman key agreement over a 3D network scene; switch on a man-in-the-middle attacker and watch two independent, mismatched session keys get established the moment authentication is off — then switch on signed-nonce authentication and watch the same attacker's substituted values get rejected by a signature check instead. A separate replay button resends a genuine, previously-valid captured packet to demonstrate why nonce caching and timestamp freshness windows are needed even when every message is properly signed.